PT-2022-19865 · Western Digital · Wd Discovery
Aaron Lemieux
·
Published
2022-09-19
·
Updated
2023-07-21
·
CVE-2022-29835
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Western Digital WD Discovery versions prior to 4.4.396
Description
The WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm, which is not collision-free. This weakness could be exploited by an attacker to create forged certificate signatures, potentially impacting the confidentiality of user content.
Recommendations
For versions prior to 4.4.396, update to version 4.4.396 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive user content until the update is applied.
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wd Discovery